US Justice Department Said to Be Investigating Data Breach at Uber

Advertisement
By Reuters | Updated: 19 December 2015 18:08 IST
The US Department of Justice is pursuing a criminal investigation of a May 2014 data breach at ride service Uber, including an examination of whether any employees at competitor Lyft were involved in the episode, sources familiar with the situation said.

Earlier this year, Uber revealed that as many as 50,000 of its drivers' names and their licence numbers had been improperly downloaded. An investigation by Uber determined that an Internet address potentially associated with the breach can be traced to Lyft's technology chief, Chris Lambert, Reuters reported in October.

(Also see:  Uber Sued Over Driver Data Breach)

Department of Justice spokesman Abraham Simmons said on Wednesday he could not confirm or deny a criminal probe. No one has been accused of any wrongdoing, and it is unclear whether anyone will ultimately be charged in connection with the breach.

Advertisement

A recently hired attorney for Lambert, former federal prosecutor Miles Ehrlich, said Lambert "had nothing to do" with the breach.

Advertisement

"Given that Uber apparently lost driver data, a law enforcement investigation is to be expected," Ehrlich said. "And the benefit is that the culprit here is going to be identified - and that's going to remove Chris' name from any conversation about Uber's data breach, as it should."

In a statement on Friday, Lyft said "we have not been contacted by the DOJ, US Attorney's office or any other state or federal government agency regarding any investigation."

Advertisement

Uber declined to comment. The people familiar with the matter could not be named because they were not authorized to speak publicly.

Search for hacker
Lyft is much smaller than Uber, which operates in more than 300 cities in 67 countries and has raised $7.4 billion (roughly Rs. 49,071 crores) from investors. The companies, based in San Francisco, compete fiercely for drivers and customers.

Advertisement

Uber learnt last year that someone downloaded its driver database, which should have been accessible only with a digital security key. A search for that key turned up a copy on the code-development site GitHub, where it had been left by mistake.

Uber then obtained information from GitHub about who had connected to that page before the breach and found only one Internet Protocol address that did not belong to an Uber user or have another plausible explanation, according to court documents.

Uber filed a civil lawsuit in San Francisco federal court in February in an attempt to unmask the perpetrator. The company's court papers claim that an unidentified person using a Comcast IP address had access to the security key.

On its own, Uber investigated that address and determined that it had been assigned to Lambert, Reuters reported in October.

A US judge ruled that Uber could further probe the IP address, saying it was "reasonably likely" that such an inquiry could help identify the hacker. That ruling is on hold pending an appeal.

Sworn statement
Attorneys for the unnamed Comcast subscriber have pointed out in court that the data breach was conducted from a different IP address than the Comcast address that accessed the security key. Lyft said that Uber allowed the key for the database "to be publicly accessible for months before and after the breach."

The IP address the hacker used is associated with Anonine, a virtual private network service based in Sweden that is known for vigorously protecting the privacy of its users, two people familiar with the situation told Reuters.

Ehrlich said Lambert offered to provide Uber with a sworn statement that he had nothing to do with the breach, made under penalty of perjury.

Lambert signed the statement over the summer, a separate source familiar with the situation said. In it, Lambert also said he was not aware of anyone who has copies of Uber's database, and that he did not instruct anyone to access it, the source said.

However, Lyft and Ehrlich declined to confirm or deny that Lambert's Comcast address connected to the GitHub page containing the key. They also declined to give details about Lyft's internal investigation of the matter.

Lyft reiterated on Friday that it investigated the matter "long ago" and concluded "there is no evidence that any Lyft employee, including Chris, downloaded the Uber driver information or database, or had anything to do with Uber's May 2014 data breach."

Uber's lawsuit alleges the hacker violated civil provisions of the federal Computer Fraud and Abuse Act, as well as a similar California law. It is unclear if the leaked driver information was ever used by the hacker or anyone else.

© Thomson Reuters 2015

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  4. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  5. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  6. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  7. Nothing Phone 3a Lite Goes on Sale in India at This Price
  8. Vivo S50 Colour Options, Key Features Surface Online Ahead of Launch
  9. OTT Releases of the Week (Dec 1 – Dec 7): Know What to Watch
  10. Realme 16 Pro+ 5G New Leak Reveals Storage and Colour Variants
  1. Motorola Edge 70 India Launch Teased; Flipkart Availability Confirmed: Expected Specifications, Features
  2. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  3. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  4. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  5. Realme 16 Pro+ 5G Colour Options, Memory Configurations Leaked Again; Tipped to Launch With 7,000mAh Battery
  6. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  7. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  8. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  9. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  10. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.